Rocket.Chat records
64 published records for vendor rocket.chat.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 18.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor10
- CWE-287 Improper Authentication6
- CWE-284 Improper Access Control4
- CWE-285 Improper Authorization3
- CWE-400 Uncontrolled Resource Consumption3
The weakness classes this vendor ships most often: where to look.
CWEAll records
64 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
68This week | CVE-2021-22911Proof of concept | A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injectiorocket.chat · rocket.chat · CWE-75 | Critical9.8 | — | 95.2% | May 27, 2021 |
40Plan | CVE-2021-22910No exploit | A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which couldrocket.chat · rocket.chat · CWE-75 | Critical9.8 | — | 2.3% | Aug 9, 2021 |
40Plan | CVE-2017-1000493No exploit | Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeoverrocket.chat · rocket.chat · CWE-74 | Critical9.8 | — | 1.7% | Jan 2, 2018 |
39Monitor | CVE-2022-44567No exploit | A command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an attacker to pass a malicious url of openInternalrocket.chat · rocket.chat · CWE-78 | Critical9.8 | — | 1.7% | Dec 23, 2022 |
39Monitor | CVE-2020-29594No exploit | Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 mishandles SAMLrocket.chat · rocket.chat | Critical9.8 | — | 1.6% | Dec 30, 2020 |
39Monitor | CVE-2023-28316No exploit | A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not irocket.chat · rocket.chat · CWE-384 | Critical9.8 | — | 0.7% | May 9, 2023 |
39Monitor | CVE-2026-29198Proof of concept | In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account trocket.chat · rocket.chat · CWE-89 | Critical9.8 | — | 0.6% | Apr 22, 2026 |
39Monitor | CVE-2026-58066No exploit | Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did nrocket.chat · rocket.chat · CWE-287 | Critical9.8 | — | 0.4% | Jul 30, 2026 |
37Monitor | CVE-2026-28514No exploit | Rocket.Chat: Users can login with any password via the EE ddp-streamer-servicerocket.chat · rocket.chat · CWE-287 | Critical9.3 | — | 0.7% | Mar 6, 2026 |
37Monitor | CVE-2026-48616No exploit | Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files.rocket.chat · rocket.chat · CWE-284 | Critical9.3 | — | 0.4% | Jun 17, 2026 |
35Monitor | CVE-2024-39713Proof of concept | A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.rocket.chat · rocket.chat · CWE-918 | High8.6 | — | 3.2% | Aug 5, 2024 |
35Monitor | CVE-2022-35248No exploit | A improper authentication vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 that allowed two factor authentication can be bypasserocket.chat · rocket.chat · CWE-287 | High8.8 | — | 1.4% | Sep 23, 2022 |
35Monitor | CVE-2022-32211No exploit | A SQL injection vulnerability exists in Rocket.Chat <v3.18.6, <v4.4.4 and <v4.7.3 which can allow an attacker to retrieve a reset password trocket.chat · rocket.chat · CWE-89 | High8.8 | — | 1.4% | Sep 23, 2022 |
35Monitor | CVE-2023-23917No exploit | A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the admin account.rocket.chat · rocket.chat · CWE-77 | High8.8 | — | 1.0% | Feb 23, 2023 |
32Monitor | CVE-2026-30831No exploit | Rocket.Chat: 2FA bypass and login of deactivated users via EE ddp-streamerrocket.chat · rocket.chat · CWE-287 | High8.0 | — | 0.6% | Mar 6, 2026 |
31Monitor | CVE-2021-22892No exploit | An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be drocket.chat · rocket.chat · CWE-200 | High7.5 | — | 1.9% | May 27, 2021 |
30Monitor | CVE-2026-48929No exploit | Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletionrocket.chat · rocket.chat · CWE-287 | High7.5 | — | 0.9% | Jun 17, 2026 |
30Monitor | CVE-2020-26763No exploit | The Rocket.Chat desktop application 2.17.11 opens external links without user interaction.rocket.chat · rocket.chat | High7.5 | — | 0.8% | Jul 5, 2021 |
30Monitor | CVE-2023-28356No exploit | A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to enterocket.chat · rocket.chat · CWE-400 | High7.5 | — | 0.7% | May 11, 2023 |
30Monitor | CVE-2024-46935No exploit | Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS).rocket.chat · rocket.chat | High7.5 | — | 0.6% | Sep 24, 2024 |
30Monitor | CVE-2026-65644No exploit | Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/liverocket.chat · rocket.chat · CWE-79 | High7.5 | — | 0.5% | Aug 21, 2026 |
30Monitor | CVE-2025-7974No exploit | rocket.chat Incorrect Authorization Information Disclosure Vulnerabilityrocket.chat · rocket.chat · CWE-863 | High7.5 | — | 0.4% | Sep 2, 2025 |
30Monitor | CVE-2023-23911No exploit | An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a userocket.chat · rocket.chat · CWE-284 | High7.5 | — | 0.3% | Mar 10, 2023 |
27Monitor | CVE-2022-30124No exploit | An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a mrocket.chat · rocket.chat · CWE-287 | Medium6.8 | — | 0.6% | Sep 23, 2022 |
27Monitor | CVE-2026-30833No exploit | Rocket.Chat: NoSQL injection in the EE ddp-streamer-servicerocket.chat · rocket.chat · CWE-943 | Medium6.9 | — | 0.4% | Mar 6, 2026 |
- CVE-2021-2291168This week
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injectio
CriticalCVSS 9.8Proof of conceptEPSS 95%rocket.chat · rocket.chatMay 27, 2021
- CVE-2021-2291040Plan
A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could
CriticalCVSS 9.8No exploitEPSS 2%rocket.chat · rocket.chatAug 9, 2021
- CVE-2017-100049340Plan
Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover
CriticalCVSS 9.8No exploitEPSS 2%rocket.chat · rocket.chatJan 2, 2018
- CVE-2022-4456739Monitor
A command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an attacker to pass a malicious url of openInternal
CriticalCVSS 9.8No exploitEPSS 2%rocket.chat · rocket.chatDec 23, 2022
- CVE-2020-2959439Monitor
Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 mishandles SAML
CriticalCVSS 9.8No exploitEPSS 2%rocket.chat · rocket.chatDec 30, 2020
- CVE-2023-2831639Monitor
A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not i
CriticalCVSS 9.8No exploitEPSS 1%rocket.chat · rocket.chatMay 9, 2023
- CVE-2026-2919839Monitor
In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account t
CriticalCVSS 9.8Proof of conceptEPSS 1%rocket.chat · rocket.chatApr 22, 2026
- CVE-2026-5806639Monitor
Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did n
CriticalCVSS 9.8No exploitEPSS 0%rocket.chat · rocket.chatJul 30, 2026
- CVE-2026-2851437Monitor
Rocket.Chat: Users can login with any password via the EE ddp-streamer-service
CriticalCVSS 9.3No exploitEPSS 1%rocket.chat · rocket.chatMar 6, 2026
- CVE-2026-4861637Monitor
Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files.
CriticalCVSS 9.3No exploitEPSS 0%rocket.chat · rocket.chatJun 17, 2026
- CVE-2024-3971335Monitor
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
HighCVSS 8.6Proof of conceptEPSS 3%rocket.chat · rocket.chatAug 5, 2024
- CVE-2022-3524835Monitor
A improper authentication vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 that allowed two factor authentication can be bypasse
HighCVSS 8.8No exploitEPSS 1%rocket.chat · rocket.chatSep 23, 2022
- CVE-2022-3221135Monitor
A SQL injection vulnerability exists in Rocket.Chat <v3.18.6, <v4.4.4 and <v4.7.3 which can allow an attacker to retrieve a reset password t
HighCVSS 8.8No exploitEPSS 1%rocket.chat · rocket.chatSep 23, 2022
- CVE-2023-2391735Monitor
A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the admin account.
HighCVSS 8.8No exploitEPSS 1%rocket.chat · rocket.chatFeb 23, 2023
- CVE-2026-3083132Monitor
Rocket.Chat: 2FA bypass and login of deactivated users via EE ddp-streamer
HighCVSS 8.0No exploitEPSS 1%rocket.chat · rocket.chatMar 6, 2026
- CVE-2021-2289231Monitor
An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be d
HighCVSS 7.5No exploitEPSS 2%rocket.chat · rocket.chatMay 27, 2021
- CVE-2026-4892930Monitor
Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletion
HighCVSS 7.5No exploitEPSS 1%rocket.chat · rocket.chatJun 17, 2026
- CVE-2020-2676330Monitor
The Rocket.Chat desktop application 2.17.11 opens external links without user interaction.
HighCVSS 7.5No exploitEPSS 1%rocket.chat · rocket.chatJul 5, 2021
- CVE-2023-2835630Monitor
A vulnerability has been identified where a maliciously crafted message containing a specific chain of characters can cause the chat to ente
HighCVSS 7.5No exploitEPSS 1%rocket.chat · rocket.chatMay 11, 2023
- CVE-2024-4693530Monitor
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS).
HighCVSS 7.5No exploitEPSS 1%rocket.chat · rocket.chatSep 24, 2024
- CVE-2026-6564430Monitor
Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/live
HighCVSS 7.5No exploitEPSS 0%rocket.chat · rocket.chatAug 21, 2026
- CVE-2025-797430Monitor
rocket.chat Incorrect Authorization Information Disclosure Vulnerability
HighCVSS 7.5No exploitEPSS 0%rocket.chat · rocket.chatSep 2, 2025
- CVE-2023-2391130Monitor
An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a use
HighCVSS 7.5No exploitEPSS 0%rocket.chat · rocket.chatMar 10, 2023
- CVE-2022-3012427Monitor
An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a m
MediumCVSS 6.8No exploitEPSS 1%rocket.chat · rocket.chatSep 23, 2022
- CVE-2026-3083327Monitor
Rocket.Chat: NoSQL injection in the EE ddp-streamer-service
MediumCVSS 6.9No exploitEPSS 0%rocket.chat · rocket.chatMar 6, 2026